The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,155
Mitigations16,675
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
mediasoup>= 3.20.0, <= 3.20.5
NPM: mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
5.6
15 minutes ago
FundEngine<= 1.8.1
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
43 minutes ago
Advanced Product Fields (Product Addons) for WooCommerce<= 1.6.21
Unauthenticated Improper Input Validation to Price Bypass vulnerability
7.5
46 minutes ago
WS Form LITE<= 1.10.80
Unauthenticated PHP Object Injection vulnerability
9.8
46 minutes ago
Events Manager<= 7.3.7.4
Authenticated (Administrator+) Local File Inclusion vulnerability
7.5
47 minutes ago
ManageWP Worker< 4.9.37
Unauthenticated Authentication Bypass vulnerability
9.8
1 hour ago
FiboSearch< 1.34.1
Unauthenticated Password-Protected Product Information Disclosure vulnerability
7.5
1 hour ago
Limit Login Attempts Reloaded< 3.3.5
Username Denylist Bypass vulnerability
3.7
1 hour ago
All-in-One WP Migration<= 7.109
Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution vulnerability
8.8
1 hour ago
ShopEngine<= 4.9.4
Authenticated (Shop Manager+) Privilege Escalation to WXR Import 'plugin <wp_option>' Nodes vulnerability
7.2
1 hour ago
Metform<= 4.1.8
Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting vulnerability
6.5
1 hour ago
eCommerce Product Catalog<= 3.5.10
Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute vulnerability
6.5
1 hour ago
@platejs/media>= 53.0.0, < 53.1.4
NPM: Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
8.7
2 hours ago
browse-mcp<= 0.8.1
NPM: browse-mcp has an arbitrary file write via unconfined download and state paths
8.6
2 hours ago
Newsletters<= 4.17
Authenticated (Author+) Arbitrary Modification via 'newsletters_mailinglistsroles' POST Parameter vulnerability
4.3
2 hours ago
Media Sweep – WordPress Media Cleaner<= 1.1.3
Authenticated (Administrator+) SQL Injection via 'fields' Parameter vulnerability
7.6
2 hours ago
My Agile Privacy<= 3.3.6
Missing Authorization to Unauthenticated Plugin Settings Modification via map_missing_cookie_shield / map_check_consent_mode_status AJAX Actions vulnerability
5.3
2 hours ago
urllib<= 2.44.0
NPM: urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
7.5
2 hours ago
pickem< 1.0.7
NPM: pickem vulnerable to terminal escape-sequence injection via unsanitized item text
8.6
2 hours ago
Drag and Drop Multiple File Upload for WooCommerce< 1.1.8
Unauthenticated File Deletion via Nonce Oracle vulnerability
6.5
5 hours ago